CVE-2016-1607 describes multiple Cross-Site Request Forgery (CSRF) vulnerabilities in the administrative interface of Novell Filr versions prior to 2.0 Security Update 2. These flaws allow remote attackers to hijack administrator authentication, enabling unauthorized actions like reconfiguring time settings. The vulnerability carries a high CVSS score of 7.2, indicating a network-based attack with low complexity, requiring high privileges, and leading to high impacts on confidentiality, integrity, and availability. While not listed on the KEV catalog, exploit code exists (EDB-40161), and it has garnered significant community discussion and media coverage, suggesting awareness among threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.2CPE matchmatch criteria | cpe:2.3:a:novell:filr:*:security_update_2:*:*:*:*:*:* | ||
<= 2.0CPE matchmatch criteria | cpe:2.3:a:novell:filr:*:security_update_1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.